Total vulnerabilities in the database
Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "//UNION " or (2) " UNION//" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.
Software | From | Fixed in |
---|---|---|
phpnuke / php-nuke | 7.3 | 7.3.x |
phpnuke / php-nuke | 7.4 | 7.4.x |
phpnuke / php-nuke | 7.1 | 7.1.x |
phpnuke / php-nuke | - | 7.9.x |
phpnuke / php-nuke | 7.5 | 7.5.x |
phpnuke / php-nuke | 7.2 | 7.2.x |
phpnuke / php-nuke | 7.7 | 7.7.x |
phpnuke / php-nuke | 7.8 | 7.8.x |
phpnuke / php-nuke | 7.0 | 7.0.x |
phpnuke / php-nuke | 7.6 | 7.6.x |